VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 39 of 1,041
  • CVE-2026-31877CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in…

  • CVE-2026-3843CriMar 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter…

  • CVE-2025-40639CriMar 9, 2026
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.

  • CVE-2026-30860CriMar 7, 2026
    risk 0.64cvss 9.9epss 0.01

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect…

  • CVE-2026-28785CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all…

  • CVE-2026-27005CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL,…

  • CVE-2026-28443CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0.

  • CVE-2025-66944CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

  • CVE-2025-66678CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.

  • CVE-2025-70821CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component

  • CVE-2026-26713CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

  • CVE-2026-26712CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

  • CVE-2026-26711CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

  • CVE-2026-26710CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

  • CVE-2026-26709CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

  • CVE-2026-26707CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.

  • CVE-2026-26706CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.

  • CVE-2026-26705CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.

  • CVE-2026-26704CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.

  • CVE-2026-26708CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.